Jobs › Companies › Core Specialty Insurance › IT GRC - Risk Analyst

Sobre esta vaga de IT GRC - Risk Analyst na Core Specialty Insurance

Core Specialty Insurance · Híbrido · Cincinnati, OH

-

The IT GRC - Risk Analyst supports the IT Governance, Risk, Compliance (GRC) team by helping assess, monitor, and manage technology and cybersecurity risks associated with vendors, suppliers, service providers, and other third parties. This role helps ensure third-party relationships are reviewed in alignment with internal policies, regulatory expectations, contractual requirements, and recognized frameworks such as NIST, COBIT, SOC 2, and applicable cybersecurity and privacy requirements.


The IT GRC - Risk Analyst works closely with IT, cybersecurity, procurement, legal, compliance, business owners, and vendors to support vendor risk assessments, evidence collection, questionnaire reviews, issue tracking, remediation follow-up, and ongoing monitoring activities. The role helps strengthen the organization’s third-party risk management program by identifying risks, documenting findings, and supporting timely, risk-based decisions.


Key Accountabilities/Deliverables:

  • Support the execution of the third-party risk management process as part of the IT GRC team, including initial assessments, reassessments, ongoing monitoring, and remediation tracking.
  • Conduct third-party risk assessments by reviewing vendor questionnaires, security documentation, SOC reports, certifications, policies, penetration test summaries, business continuity information, and other relevant evidence.
  • Identify and document third-party technology, cybersecurity, privacy, operational, and compliance risks based on vendor responses and supporting documentation.
  • Work with business owners, IT teams, cybersecurity, legal, procurement, compliance, and vendors to collect required information and resolve assessment gaps.
  • Review vendor control environments against internal requirements, regulatory expectations, and applicable frameworks.
  • Support risk rating activities by evaluating vendor criticality, data sensitivity, service type, system access, control maturity, and potential business impact.
  • Track third-party risk findings, remediation plans, risk acceptances, exceptions, and outstanding vendor information requests through completion.
  • Maintain accurate and organized assessment records, evidence, risk summaries, vendor profiles, decision documentation, and approval artifacts.
  • Support ongoing vendor monitoring activities, including security rating changes, alerts, performance indicators, contract or service changes, and emerging third-party risks.
  • Prepare clear assessment summaries, risk reports, dashboards, status updates, and escalation materials for management review.
  • Escalate significant vendor risks, overdue remediation items, missing information, control concerns, and high-risk third-party relationships to IT GRC leadership.
  • Assist with improving third-party risk processes, assessment templates, questionnaires, workflows, reporting, evidence standards, and monitoring practices.
  • Support audit and regulatory readiness by maintaining third-party risk documentation and responding to requests related to vendor risk management activities.

Technical Knowledge and Understanding:

  • Understanding of third-party risk management principles, including vendor due diligence, risk assessments, ongoing monitoring, issue tracking, and risk-based decision-making.
  • Working knowledge of cybersecurity, IT risk, privacy, and compliance concepts relevant to third-party service providers.
  • Familiarity with frameworks, standards, and reports such as NIST CSF, ISO 27001, COBIT, SOC 1, SOC 2, PCI DSS, HIPAA, NYDFS, and other applicable requirements.
  • Understanding of common vendor risk areas, including access management, data protection, encryption, vulnerability management, incident response, logging and monitoring, business continuity, disaster recovery, subcontractor risk, and cloud/SaaS security.
  • Ability to review vendor questionnaires, SOC reports, certifications, policies, security summaries, and other evidence to identify control gaps and risk concerns.
  • Knowledge of third-party risk rating concepts, including vendor criticality, inherent risk, residual risk, data sensitivity, control maturity, and remediation priority.
  • Strong analytical, documentation, communication, and follow-up skills, with the ability to summarize risks clearly for technical and non-technical stakeholders.
  • Ability to manage multiple vendor assessments, track deadlines, follow up on open items, and maintain audit-ready assessment documentation.
  • Professional certifications such as Security+, CISA, CRISC, CTPRP, ISO 27001 Foundation, or similar certifications are a plus.

Requirements:

Applicants must be authorized to work for any employer in the U.S.  We are unable to sponsor or take over work authorization sponsorship now or in the future for this position. 


  • Bachelor’s degree in Information Systems, Cybersecurity, Risk Management, Information Assurance, Business Administration, or related field; or equivalent work experience.
  • 3+ years of experience in IT Governance, Risk Management, Compliance (GRC), IT Audit, Cybersecurity, Internal Controls, or a related technology risk function.
  • Experience supporting technology and cybersecurity risk assessments, risk analysis, control evaluations, compliance reviews, or governance activities.
  • Knowledge of IT risk management principles, control frameworks, risk treatment strategies, remediation tracking, and issue management practices.
  • Experience documenting and maintaining risk registers, findings, remediation plans, exceptions, and governance artifacts.
  • Experience supporting compliance with regulatory and industry frameworks such as NIST CSF, ISO 27001, COBIT, NYDFS, HIPAA, SOX, or similar standards.
  • Experience supporting internal audits, external audits, regulatory examinations, customer due diligence reviews, or compliance assessments.
  • Experience collaborating with Information Security, IT Operations, Application Owners, Compliance, Legal, Internal Audit, and business stakeholders to manage risk and remediation activities.
  • Experience developing risk metrics, dashboards, reports, and management summaries for governance and risk reporting.
  • Experience using GRC, workflow, reporting, and collaboration tools such as Jira, Confluence, SharePoint, Microsoft 365, Power BI, or similar platforms.
  • Strong analytical, organizational, communication, and problem-solving skills with the ability to assess risks and communicate recommendations effectively.
  • Professional certifications such as CRISC, CISA, CISM, CGRC, CISSP, or similar certifications preferred.
  • Experience within insurance, financial services, healthcare, or other regulated industries preferred.




#LI-Hybrid





-

At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement.  We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program

Pronto para se candidatar à Core Specialty Insurance?
Candidatar-se à Core Specialty Insurance

Sobre a Core Specialty Insurance

Core Specialty offers a diversified range of property and casualty insurance products for small to mid-sized businesses. From underwriting offices spanning the U.S., the Company focuses on niche markets, local distribution, and superior underwriting knowledge, offering traditional as well as innovative insurance solutions to meet the needs of its customers and brokers. For further information about Core Specialty, please visit www.corespecialtyinsurance.com . In compliance with the Transparency in Coverage rule, issued in 2020 by US Departments of Health, Human Services, Labor and Treasury our health plan’s machine-readable files (MRFs) can be accessed via www.Cigna.com .

Ver todas as vagas na Core Specialty Insurance →

Vagas semelhantes

CS
IT GRC Lead Analyst
Core Specialty Insurance
⚡ Candidate-se cedo Cincinnati, OH Híbrido
● Nova 👁 Vista ✓ Candidatada há 1d
U.S. Bank
Operational Risk Review (ORR) Analyst
U.S. Bank
⚡ Candidate-se cedo Minneapolis, MN Presencial $92,820–$109,200
● Nova 👁 Vista ✓ Candidatada há 2d
U.S. Bank
GB&L Compliance Risk Manager - Corporate Payment Systems
U.S. Bank
⚡ Candidate-se cedo Cincinnati, OH Presencial $111,605–$131,300
● Nova 👁 Vista ✓ Candidatada há 3d
U.S. Bank
Risk Manager - Wealth, Corporate, Commercial and Institutional Banking
U.S. Bank
⚡ Candidate-se cedo Tempe, AZ Presencial $126,820–$149,200
● Nova 👁 Vista ✓ Candidatada há 3sem
Huntington Bank
Asset Finance Risk Manager Sr
Huntington Bank
⚡ Candidate-se cedo Cincinnati, OH Presencial $120,000–$189,000
● Nova 👁 Vista ✓ Candidatada há 3sem
Great American Insurance Group
Underwriting Territory Manager – Cyber Risk
Great American Insurance Group
⚡ Candidate-se cedo Remote (USA) · local restrito $150,000–$225,000
● Nova 👁 Vista ✓ Candidatada há 1m
Great American Insurance Group
Analytics Manager - Great American Risk Solutions
Great American Insurance Group
⚡ Candidate-se cedo Cincinnati, OH (USA) Presencial
● Nova 👁 Vista ✓ Candidatada há 1m
KeyBank
Sr. Compliance Manager – Operational Risk Testing
KeyBank
⚡ Candidate-se cedo Brooklyn, OH Presencial $112,000–$210,000
● Nova 👁 Vista ✓ Candidatada há 1m
PwC
Risk & Independence Contract Specialist Senior Manager - Managed Services
PwC
⚡ Candidate-se cedo FL-Tampa Presencial $91,000–$321,500
● Nova 👁 Vista ✓ Candidatada há 2m

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na Core Specialty Insurance

Ver todas as vagas na Core Specialty Insurance →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis